Netskope Threat Labs

FILE-OTHER Tablib yaml.load code execution attempt

IPS-SWG

1 SID: 42195

First seen
February 2025
Last seen
February 2025

Detects content exploiting CVE-2017-2810, unsafe YAML deserialization in the Tablib library that runs Python objects from crafted data files. The rule matches the object instantiation tags that public exploits use to execute code on the server.